$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: an Apache/2.4.49 host exposed CGI path traversal RCE, which led to local service enumeration and a PHP-FPM pivot. Solution: use FastCGI to read edvard's secret, log in over SSH, then exploit ExifTool 12.20 through a sudo image-scanning script to recover the root half of the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar